Cross-Site Scripting in Disqus Comment System Plugin for WordPress
CVE-2014-5345
Currently unrated
Summary
The Disqus Comment System plugin for WordPress contains a cross-site scripting (XSS) vulnerability in its upgrade.php file. This flaw allows remote attackers to inject arbitrary web scripts or HTML into a website by manipulating the 'step' parameter. Exploitation of this vulnerability can lead to unauthorized actions being executed on behalf of a user or the exposure of sensitive information. Users of affected versions are strongly advised to update to the latest version to mitigate the risk.
References
Timeline
Vulnerability Reserved
Vulnerability published